Input validation error in OpenSSL - CVE-2014-3510

 

Input validation error in OpenSSL - CVE-2014-3510

Published: August 14, 2014 / Updated: February 16, 2021


Vulnerability identifier: #VU41412
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2014-3510
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows remote DTLS servers to perform a denial of service (DoS) attack.

The vulnerability exists due to insufficient validation of user-supplied input. A remote attacker can cause a denial of service (NULL pointer dereference and client application crash) via a crafted handshake message in conjunction with a (1) anonymous DH or (2) anonymous ECDH ciphersuite.


Affected software

OpenSSL
Amazon Linux AMI
Gentoo Linux
Fedora
Slackware Linux
HP Insight Control
HP-UX
FlashSystem V840 9846-AE1 & 9848-AE1
FlashSystem 840 9840-AE1 & 9843-AE1
SSL for OpenVMS
TMS RAMSAN 710 & 810 Machine Type 9833 -AS1 & -AE1
FlashSystem 710 & 810 Machine Type 9830 -AS1 & -AE1
IBM FlashSystem 720 and 820 Machine Type 9831 –AS2 and -AE2
TMS RAMSAN 720 and 820 machine type 9834 -AS2 & AE2
FlashSystem V840 9846-AC0 & -AC1 and 9848-AC0 & -AC1
mingw-openssl
IBM Storwize V7000
IBM Storwize V5000
IBM Storwize V3700
IBM Storwize V3500
SAN Volume Controller and Storwize Family

How to mitigate CVE-2014-3510

Install update from vendor's website.

mingw-openssl - addressed in versions 1.0.1j-1.el7, 1.0.1j-1.fc21
FlashSystem V840 9846-AE1 & 9848-AE1 - update to 1.1.2.7
FlashSystem 840 9840-AE1 & 9843-AE1 - update to 1.1.2.7
SSL for OpenVMS - update to 1.4-493
TMS RAMSAN 710 & 810 Machine Type 9833 -AS1 & -AE1 - update to 5.6.2
FlashSystem 710 & 810 Machine Type 9830 -AS1 & -AE1 - update to 5.6.2
IBM FlashSystem 720 and 820 Machine Type 9831 –AS2 and -AE2 - update to 6.3.2
TMS RAMSAN 720 and 820 machine type 9834 -AS2 & AE2 - update to 6.3.2
IBM Storwize V7000 - update to 7.2.0.9
IBM Storwize V5000 - addressed in versions 7.2.0.9, 7.3.0.7, 7.4.0.0
SAN Volume Controller and Storwize Family - addressed in versions 7.2.0.9, 7.3.0.7, 7.4.0.0
IBM Storwize V3700 - addressed in versions 7.2.0.9, 7.3.0.7, 7.4.0.0
IBM Storwize V3500 - addressed in versions 7.2.0.9, 7.3.0.7, 7.4.0.0
FlashSystem V840 9846-AC0 & -AC1 and 9848-AC0 & -AC1 - update to 7.3.0.7

External References

Related Security Bulletins